Direct identifiers
Company names and domains are the clearest starting points. Spelling, subsidiaries, brands, and shared names can affect the result.
This page documents the production workflow behind the free domain scan and paid monitoring profiles. It also states what the result cannot prove.
Last reviewed: July 11, 2026
AdverseMonitor tracks publicly posted cyber-incident claims — ransomware and extortion leak-site posts, data-breach and data-leak listings, DDoS, defacement and initial-access offers — drawn from sources including Telegram channels, Tor sites and the open web, and raises a dashboard alert when your organisation, domain, industry or country is named. A result is an investigation lead with source evidence. It is not automatic proof that a network was compromised, and it is not a guarantee that every relevant source has been collected.
Company names and domains are the clearest starting points. Spelling, subsidiaries, brands, and shared names can affect the result.
Industry, country, category, and threat actor criteria help narrow a monitoring profile. They do not identify a company by themselves.
Check a domain or read the security controls and API behavior.